← Vulnerability feed

Vulnerability record · CVE-2023-20888 · published 7 June 2023

CVE-2023-20888: VMware Aria Operations for Networks authenticated deserialization RCE

Vmware · Vrealize Network Insight

VMware Aria Operations for Networks (vRealize Network Insight) contains a deserialization of untrusted data flaw (CWE-502). An attacker with valid 'member' role credentials and network access can trigger a deserialization attack that leads to remote code execution. The flaw matters because it turns low-privilege authenticated access into full code execution on a management platform.

8.8 CVSS 3.1 High EPSS 82% · top 0.3% CWE-502 · Deserialization of untrusted data
8.8CVSS 3.1 base score
82%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Aria Operations for Networks contains an authenticated deserialization vulnerability. A malicious actor with network access to VMware Aria Operations for Networks and valid 'member' role credentials may be able to perform a deserialization attack resulting in remote code execution.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityAuthenticated network-reachable RCE with high CVSS (8.8) and very high EPSS, though it requires valid low-privilege credentials and no KEV listing or confirmed public exploit.

What it is

VMware Aria Operations for Networks (vRealize Network Insight) contains a deserialization of untrusted data flaw (CWE-502). An attacker with valid 'member' role credentials and network access can trigger a deserialization attack that leads to remote code execution. The flaw matters because it turns low-privilege authenticated access into full code execution on a management platform.

Impact

An attacker gains remote code execution on the affected appliance, with high impact to confidentiality, integrity and availability. This can lead to full compromise of the Aria Operations for Networks deployment and any data or credentials it holds.

Attack surface

Reached over the network (AV:N) by an authenticated user holding valid 'member' role credentials; no user interaction is required (UI:N). The attack requires low privileges (PR:L) but no special network position beyond connectivity to the product.

Exploitation

Not listed in CISA KEV and no ransomware usage documented. EPSS is very high (0.82282, 99.6th percentile), and the only references are the vendor advisory tagged Patch and Vendor Advisory, so no public exploit code is confirmed in this record.

What to do

  • Apply the patch from VMware advisory VMSA-2023-0012 as the first action.
  • Restrict network access to Aria Operations for Networks management interfaces to trusted networks only.
  • Review and minimize accounts holding the 'member' role; remove or disable unused accounts.
  • Rotate credentials and secrets that were accessible to any account that may have been abused.
  • Monitor for unexpected process execution or outbound connections from the appliance after patching.

Detection

  • Alert on unusual child processes or command execution spawned by the Aria Operations for Networks application or its Java runtime.
  • Monitor authentication logs for 'member' role logins from new or unexpected source IPs.
  • Watch for anomalous outbound network connections from the appliance to untrusted hosts.
  • Correlate deserialization-related errors or crashes in application logs with subsequent process activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-20888 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-31702Vmware vrealize network insight command injection vulnerabilityvRealize Network Insight (vRNI) contains a command injection vulnerability present in the vRNI REST API. A malicious actor with network access to the…EPSS 1.7%7.5CVE-2023-20889VMware Aria Operations for Networks command injection information disclosureVMware Aria Operations for Networks (formerly vRealize Network Insight) contains a command injection flaw (CWE-77) that lets a remote attacker disclo…EPSS 79%analysed9.8CVE-2021-23758Ajax.NET Professional ajaxpro.2 untrusted deserialization RCEAll versions of the ajaxpro.2 package (Ajax.NET Professional) deserialize untrusted data and permit deserialization of arbitrary .NET classes. That l…KEVEPSS 83%analysed9.8CVE-2026-63077JetBrains TeamCity unauthenticated RCE via agent polling deserializationJetBrains TeamCity before 2026.1.3 and 2025.11.7 deserializes untrusted data received through the agent polling protocol, allowing unauthenticated re…KEVEPSS 9.8%analysed9.8CVE-2026-50522Microsoft SharePoint deserialization flaw allows remote code executionMicrosoft SharePoint Server deserializes untrusted data, letting an unauthorized attacker run code over the network. The flaw is remotely reachable w…KEVEPSS 3.0%analysed9.8CVE-2026-58644Microsoft SharePoint deserialization flaw allows remote code executionMicrosoft SharePoint Server deserializes untrusted data, letting an unauthenticated network attacker execute code. The flaw is rated CVSS 9.8 critica…KEVEPSS 16%analysed8.8CVE-2026-45659Microsoft SharePoint Server deserialization flaw enables remote code executionMicrosoft SharePoint Server deserializes untrusted data, letting an authenticated attacker run code over the network. The flaw is remotely reachable,…KEVEPSS 2.7%analysed9.3CVE-2026-12569PTC Windchill PDMlink and FlexPLM deserialization RCEPTC Windchill PDMlink and FlexPLM contain a deserialization of untrusted data flaw (also classified as improper input validation) that allows remote …KEVEPSS 46%analysed

Source: NIST National Vulnerability Database (record CVE-2023-20888), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.